Executive brief
NAKIVO Backup & Replication contains an absolute path traversal vulnerability in the getImageByPath function at the /c/router endpoint. An unauthenticated attacker can exploit this to read arbitrary files, which may lead to remote code execution due to the exposure of cleartext credentials in PhysicalDiscovery.
Affected products
- NAKIVO Backup & Replication before 11.0.0.88174
Timeline
- 2025-03-04: disclosed: Initial CVE publication and MITRE analysis
- 2025-03-19: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2025-03-19: exploited: Confirmed as exploited in the wild by CISA